Identifier Collision Vulnerability in JupyterHub Affects User OAuth Clients
CVE-2026-108752

2.3LOW

Key Information:

Vendor

Jupyterhub

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108752?

JupyterHub versions up to 6.0.1 are affected by a vulnerability that allows authenticated users to overwrite another user's named server OAuth client. This occurs when a user registers a hyphenated username, such as 'alice-prod', enabling the attacker to hijack OAuth credentials associated with the legitimate user 'alice' on their server named 'prod'. This can disrupt OAuth logins and revoke access tokens, potentially causing significant security concerns.

Affected Version(s)

jupyterhub 0 <= 6.0.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.